From the Field: Weak Local Admin

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฐ๐Ÿณ.๐Ÿฒ%ย of infrastructures Iโ€™ve assessed ๐˜‚๐˜€๐—ฒ ๐˜„๐—ฒ๐—ฎ๐—ธ ๐—ผ๐—ฟ ๐˜€๐—ต๐—ฎ๐—ฟ๐—ฒ๐—ฑ ๐—น๐—ผ๐—ฐ๐—ฎ๐—น ๐—ฎ๐—ฑ๐—บ๐—ถ๐—ป๐—ถ๐˜€๐˜๐—ฟ๐—ฎ๐˜๐—ผ๐—ฟ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€

๐—œ๐˜โ€™๐˜€ ๐˜€๐—ต๐—ผ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ต๐—ผ๐˜„ ๐—ฐ๐—ผ๐—บ๐—บ๐—ผ๐—ป ๐˜๐—ต๐—ถ๐˜€ ๐—ถ๐˜€:

๐Ÿ”ธ One password for every server and client

๐Ÿ”ธ Sometimes two (โ€œserversโ€ vs โ€œworkstationsโ€)

๐Ÿ”ธ Almost always short, simple passwords (โ‰ค8 chars)

๐—ง๐—ต๐—ถ๐˜€ ๐—ถ๐˜€ ๐—ฎ ๐—ฑ๐—ถ๐˜€๐—ฎ๐˜€๐˜๐—ฒ๐—ฟ ๐˜„๐—ฎ๐—ถ๐˜๐—ถ๐—ป๐—ด ๐˜๐—ผ ๐—ต๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ป. Once an attacker cracks that single password, every system is theirs.

๐Ÿ‘‰ย ๐—ง๐—ต๐—ฒ ๐—ณ๐—ถ๐˜… ๐—ถ๐˜€ ๐—ณ๐—ฟ๐—ฒ๐—ฒ โ€” Microsoft Local Administrator Password Solution (LAPS):

๐—Ÿ๐—ฒ๐—ด๐—ฎ๐—ฐ๐˜† ๐—Ÿ๐—”๐—ฃ๐—ฆ (๐—ฝ๐—ฟ๐—ฒ-๐—ช๐—ฆ๐Ÿฎ๐Ÿฌ๐Ÿญ๐Ÿต & ๐—ช๐—ถ๐—ป๐Ÿญ๐Ÿฌ)

๐Ÿ”น Easy to use, rotates local admin passwords, stores them in AD.

๐—ก๐—ฒ๐˜„ ๐—Ÿ๐—”๐—ฃ๐—ฆ (๐—ฏ๐˜‚๐—ถ๐—น๐˜ ๐—ถ๐—ป๐˜๐—ผ ๐—ช๐—ถ๐—ป๐Ÿญ๐Ÿฌ&๐Ÿญ๐Ÿญ &ย ๐—ช๐—ฆ๐Ÿฎ๐Ÿฌ๐Ÿญ๐Ÿต+)

๐Ÿ”น Faster, simpler, more features:

โ†’ Stronger, more readable passphrases

โ†’ Password encryption (not just ACL protection)

โ†’ Post-authentication actions (triggered when a LAPS password is used)

If you need ๐—บ๐—ผ๐—ฟ๐—ฒ ๐˜๐—ต๐—ฎ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ฎ๐—ด๐—ฒ, commercial options likeย ๐—ฆ๐˜†๐—ป๐—ฒ๐—ฟ๐—ด๐—ถ๐˜… ๐—ฆ๐—˜๐—ฉ๐—”ย extend password management across platforms.